Interworking Handover Encryption Policy for EPS to 5GS

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In the interworking handover from EPS to 5GS, the source system does not provide a user plane encryption policy to the target network node, leading to incomplete security configurations during handover processes.

Innovation Solution

A method where a user plane encryption policy is explicitly provided to the target radio access network node, set to 'required', 'preferred', or 'not needed', by the source network node during the handover process, ensuring consistent security settings across systems.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the source system provides only user plane integrity protection policy to the target network node during handover, then the handover process follows existing protocols, but the security configuration is incomplete without encryption policy

Engineering Contradiction:
Improvesecurity configuration completenessVSAvoidhandover message structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The source network node determines and includes the user plane encryption policy in the handover request message before the handover occurs. This preliminary action ensures that the target network node receives complete security configuration information (both integrity protection policy and encryption policy) in advance, eliminating the need for additional security configuration steps after handover and ensuring complete security configuration without significantly increasing message complexity

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent combines the user plane integrity protection policy and user plane encryption policy into a single handover request message. By merging these two security policy elements into one message structure, the patent achieves complete security configuration transmission while avoiding the need for separate additional signaling messages, thus resolving the contradiction between security completeness and message structure complexity

Inventive Principle:
Principle #5Merging (Combining)

2Stability of the object's composition

If the source network node determines encryption policy based on local configuration for each radio bearer, then security policy consistency is achieved, but the processing overhead increases

Engineering Contradiction:
Improvesecurity policy consistencyVSAvoidhandover processing speed
Core Design Contradiction:
Stability of the object's compositionVSProductivity

Solution Approach 1:

The source network node changes the parameter of security policy determination from a generic system-wide policy to specific per-radio-bearer policies based on local configuration. By evaluating and setting encryption policies individually for each radio bearer (with options: required, preferred, not needed), the patent achieves consistent security policy application across different bearers while the local configuration approach actually reduces processing overhead compared to centralized policy determination for each bearer

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS20230422104A1User plane encryption policy at interworking handover from EPS and 5gs
Publication Date: 2023.12.28 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US20230422104A1 patent drawing
  • US20230422104A1 patent drawing
  • US20230422104A1 patent drawing

AI summary

A method performed by a target network node for interworking handover from an evolved packet system, EPS, to a fifth generation system, 5GS, in a mobile network is provided. The method includes receiving, from a source network node, a determined user plane, UP, encryption policy. The method further includes providing the determined UP encryption policy to a target radio access network node. Corresponding embodiments for methods performed by a source network node and a first target network node are also provided.